Cloud Provider PCM Suffers Data BreachCloud Provider PCM Suffers Data Breach
Attackers were reportedly able to compromise email and file-sharing systems for some of PCM's customers.
June 28, 2019
Cloud solution provider PCM has been hit with a data breach in which attackers reportedly accessed the email and file-sharing systems for some of its clients, KrebsOnSecurity reports.
PCM, which has 2,000-plus customers and generated about $2.2 billion in 2018, detected the breach in mid-May, sources report. Those same sources say intruders were able to steal admin credentials the company uses to handle client accounts in Office 365. It seems the attackers want to use the stolen data in gift card fraud schemes at financial organizations and retailers, according to a security expert at a PCM client who was informed of the intrusion.
In this, security experts noticed a similarity between the attack against PCM and the data breach at Wipro, which was targeted in April. Attackers behind the Wipro breach reportedly collected gift card data from customers. It has not been determined whether the Wipro and PCM incidents are related or whether PCM is the victim of a separate attack.
PCM has confirmed it recently experienced a cyber incident that affected certain systems, KrebsOnSecurity says. Its own investigation indicates the company's systems experienced "limited" impact and "minimal-to-no impact" on PCM customers. The incident has been remediated, PCM reports, and any affected customers have been made aware of it.
Earlier this week, Insight Enterprises announced plans to acquire PCM. It's unclear whether this attack will affect the transaction.
Read more details here.
Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.
About the Author(s)
You May Also Like
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
What's In Your Cloud?Nov 30, 2023
Everything You Need to Know About DNS AttacksNov 30, 2023